policy template · Free download

Acceptable Use Policy Template

IT acceptable use policy covering devices, passwords and MFA, personal phones, generative AI tools, data classes, clean desk, and monitoring notice.

Sign in with Google below to download the PDF and CSV straight away.

Get your free download

Sign in with Google to unlock the PDF and CSV instantly. No form to fill in.

Free. By continuing you agree to our terms and privacy policy. We record your email and this download; marketing emails only if you tick the box.

What you get

  • A ready-to-adopt policy with 14 sections, from scope to acknowledgement
  • A generative AI section with an approved-tools table and rules for confidential data
  • A four-level data classification table with handling rules for each level
  • A personal phone rule with safety carve-outs and a clean desk checklist
  • Electronic monitoring notice wording for Connecticut, Delaware, and New York

Template preview

A preview of the structure. Download the PDF or CSV for the complete, ready-to-use version.

Policy details

Company name
Policy owner— Usually IT or Security, with HR
Effective date and version
Where to report a security incident— Email alias, Slack channel, or phone number

1. Purpose and scope

This policy sets the rules for using [Company name]'s devices, accounts, networks, software, and data. It applies to all employees, contractors, interns, and temporary staff, on and off company premises, and to personal devices when they are used to access company systems. The goal is to protect the company, customers, and co-workers from data loss, security incidents, and legal risk while leaving people free to do their work.

2. Data classification and handling

Treat information at the highest level that applies. When unsure, ask the data owner or IT.

ClassExamplesCan share withHandling rules
PublicPublished website content, press releases, job postingsAnyoneNo restrictions
InternalOrg chart, internal announcements, most wiki pagesEmployees and contractors under NDACompany systems only; do not post publicly
ConfidentialCustomer contracts, pricing, product roadmap, source codePeople with a business needApproved systems only; encrypt in transit; no public AI tools
RestrictedPayroll, SSNs, bank details, health information, passwords, security keysNamed roles onlyEncrypted at rest and in transit; access logged; never in email body, chat, or AI tools

3. Generative AI tools

AI assistants are allowed for work when used within these rules. Public AI tools may store prompts and use them to train models, so what you paste in can leave the company's control.

Approved AI tools

ToolAccount typeAllowed data classesNotes
[Enterprise AI assistant]Company SSO accountPublic, Internal, ConfidentialContract excludes training on company data
[Code assistant]Company licensePublic, Internal, source codeNot for Restricted data or secrets
Any free or personal AI accountPersonalPublic onlyNo company, customer, or employee information

This is a preview — the full template continues in the download.

Sign in above to download the full template.

How to use this template

  1. 1

    List your real tools

    Fill the approved AI tools and approved systems tables with what your company actually licenses. A policy that names specific tools is followed far more than one that speaks in generalities.

  2. 2

    Match data classes to your data

    Put your own examples in each data classification level, such as customer contracts in Confidential and payroll files in Restricted.

  3. 3

    Check monitoring notice rules

    If you have employees in Connecticut, Delaware, or New York, you must give written notice of electronic monitoring. New York also requires a signed acknowledgment and a posted notice.

  4. 4

    Roll out with acknowledgment

    Send the policy to every employee and contractor with system access, collect a signed acknowledgment, and repeat when you add new tools or rules.

Frequently asked questions

What is an acceptable use policy?

It is the rulebook for how employees and contractors may use company devices, accounts, networks, and data. It usually covers passwords, personal use, email and internet, data handling, and monitoring, and it gives the company grounds to act when someone misuses systems. Security frameworks such as SOC 2 and ISO 27001 expect one.

Should an acceptable use policy cover AI tools like ChatGPT?

Yes. The main risk is employees pasting confidential or personal data into public AI accounts that may retain it. List the approved tools and which data classes each may receive, require human review of output, and route new tool requests through IT so you can review the vendor's data terms.

Do we have to tell employees we monitor their computers?

In Connecticut, Delaware, and New York, yes: written notice of electronic monitoring is required, and New York also requires acknowledgment and a posted notice. Elsewhere it is still good practice, because a clear notice reduces privacy claims and makes monitoring evidence easier to rely on in investigations.

Can we ban personal phones at work?

You can limit them for safety, security, and productivity reasons, such as on production floors or in areas with customer data. Keep carve-outs for emergencies, family care, and medical or accessibility needs, and avoid blanket bans on photography or recording that could restrict employees' NLRA-protected discussion of working conditions.

How is this different from a BYOD policy?

The acceptable use policy sets rules for all company systems and data. A BYOD policy adds rules specific to personal devices used for work, such as enrollment in device management, remote wipe of work data, and stipends. Most companies have both and cross-reference them.